๐บ๐ธ
cwytech
2026-06-20 13:56:19
(6 hours ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/tpot-web-high.
Bad Web Bot
Web App Attack
๐ช๐ธ
SweetHoneyPress
2026-06-19 11:00:40
(1 day ago)
WordPress honeypot: POST to /xmlrpc.php | event_id=789475 | UA: Mozilla/5.0 (Windows NT 10.0; x64) A ...
show more
WordPress honeypot: POST to /xmlrpc.php | event_id=789475 | UA: Mozilla/5.0 (Windows NT 10.0; x64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/60.0.0.0 Safari/537.36
show less
Web App Attack
Brute-Force
๐ช๐ธ
SweetHoneyPress
2026-06-19 10:45:38
(1 day ago)
WordPress honeypot: POST to /xmlrpc.php | event_id=789417 | UA: Mozilla/5.0 (Windows NT 6.2; x64) Ap ...
show more
WordPress honeypot: POST to /xmlrpc.php | event_id=789417 | UA: Mozilla/5.0 (Windows NT 6.2; x64) AppleWebKit/537.36 (KHTML, like Gecko) Firefox/99.0.0.0 Safari/537.36
show less
Web App Attack
Brute-Force
๐ช๐ธ
SweetHoneyPress
2026-06-19 10:30:22
(1 day ago)
WordPress honeypot: POST to /xmlrpc.php | event_id=789297 | UA: Mozilla/5.0 (Windows NT 6.3; x64) Ap ...
show more
WordPress honeypot: POST to /xmlrpc.php | event_id=789297 | UA: Mozilla/5.0 (Windows NT 6.3; x64) AppleWebKit/537.36 (KHTML, like Gecko) Safari/12.0.0.0 Safari/537.36
show less
Web App Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-18 12:36:00
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 78.186.126.50 (78.186.126.50.static.ttnet.com.t ...
show more
(mod_security) mod_security (id:225170) triggered by 78.186.126.50 (78.186.126.50.static.ttnet.com.tr): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 08:35:52.376927 2026] [security2:error] [pid 23308:tid 23308] [client 78.186.126.50:54230] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||paleopathologist.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "paleopathologist.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajPmKAO7XOt-EHPXN2GjTgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-06-17 13:46:02
(3 days ago)
[WedJun1715:45:56.0373662026][security2:error][pid1269506:tid1269726][client78.186.126.50:0]ModSecur ...
show more
[WedJun1715:45:56.0373662026][security2:error][pid1269506:tid1269726][client78.186.126.50:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"368\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"janus-advisory.ch\"][uri\"/xmlrpc.php\"][unique_id\"ajKlFLxFgh3RGiwXx2TNXQAAAAY\"]
show less
Hacking
Web App Attack
๐บ๐ธ
WeekendWeb
2026-06-17 11:28:16
(3 days ago)
Wordpress Vunerability attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 08:45:11
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 78.186.126.50 (78.186.126.50.static.ttnet.com.t ...
show more
(mod_security) mod_security (id:225170) triggered by 78.186.126.50 (78.186.126.50.static.ttnet.com.tr): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 04:45:06.488540 2026] [security2:error] [pid 9093:tid 9093] [client 78.186.126.50:51945] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bluesbluff.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bluesbluff.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajJekpSSbBS17nF2mG_eYQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Lino Project
2026-06-13 17:53:23
(1 week ago)
78.186.126.50 - - [13/Jun/2026:19:53:19 +0200] "POST /xmlrpc.php HTTP/1.1" 403 5231 "-" "Mozilla/5.0 ...
show more
78.186.126.50 - - [13/Jun/2026:19:53:19 +0200] "POST /xmlrpc.php HTTP/1.1" 403 5231 "-" "Mozilla/5.0 (Linux; Android 10; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Edge/96.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-06-13 13:23:12
(1 week ago)
Unauthorized access to webpage admin
Web App Attack
๐ฉ๐ช
Holger
2026-06-13 12:35:21
(1 week ago)
WordPress WebAttack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 08:44:44
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 78.186.126.50 (78.186.126.50.static.ttnet.com.t ...
show more
(mod_security) mod_security (id:225170) triggered by 78.186.126.50 (78.186.126.50.static.ttnet.com.tr): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 04:44:37.243976 2026] [security2:error] [pid 32402:tid 32402] [client 78.186.126.50:58218] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mobileonlinecasinos.co|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mobileonlinecasinos.co"] [uri "/wp-json/wp/v2/users"] [unique_id "ai0Ydd5WGlnwgYi5_RW_swAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
bigwavedave
2026-06-13 08:40:15
(1 week ago)
Wordpress Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 09:41:19
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 78.186.126.50 (78.186.126.50.static.ttnet.com.t ...
show more
(mod_security) mod_security (id:225170) triggered by 78.186.126.50 (78.186.126.50.static.ttnet.com.tr): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 05:41:12.386225 2026] [security2:error] [pid 9373:tid 9373] [client 78.186.126.50:62297] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mariettacaseyclub.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mariettacaseyclub.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aivUOEdbcR29azNFKtR0oQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-06-12 09:14:05
(1 week ago)
78.186.126.50 - - [12/Jun/2026:11:12:29 +0200] "POST /xmlrpc.php HTTP/1.1" 200 6476 "-" "Mozilla/5.0 ...
show more
78.186.126.50 - - [12/Jun/2026:11:12:29 +0200] "POST /xmlrpc.php HTTP/1.1" 200 6476 "-" "Mozilla/5.0 (Linux; Android 10; x64) AppleWebKit/537.36 (KHTML, like Gecko) Edge/90.0.0.0 Safari/537.36"
78.186.126.50 - - [12/Jun/2026:11:13:43 +0200] "POST /xmlrpc.php HTTP/1.1" 200 6476 "-" "Mozilla/5.0 (Windows NT 10.0; x86) AppleWebKit/537.36 (KHTML, like Gecko) Safari/12.0.0.0 Safari/537.36"
78.186.126.50 - - [12/Jun/2026:11:14:02 +0200] "POST /xmlrpc.php HTTP/1.1" 200 6476 "-" "Mozilla/5.0 (Windows NT 6.2; x86) AppleWebKit/537.36 (KHTML, like Gecko) Safari/15.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack